Register FAQ / Rules Forum Spy Search Today's Posts Mark Forums Read
Go Back   MacRumors Forums > Apple Systems and Services > OS X

Reply
 
Thread Tools Search this Thread Display Modes
Old Mar 27, 2010, 04:52 AM   #1
multimania
macrumors member
 
Join Date: Nov 2007
Port 53 Firewall connection attempt

Hi guys, i keep getting this show up in my log:

27/03/2010 09:49:21 Firewall[7800] Stealth Mode connection attempt to UDP 10.0.1.2:59861 from 10.0.1.1:53
27/03/2010 09:49:28 Firewall[7800] Stealth Mode connection attempt to UDP 10.0.1.2:58984 from 10.0.1.1:53
27/03/2010 09:49:29 Firewall[7800] Stealth Mode connection attempt to UDP 10.0.1.2:61034 from 10.0.1.1:53
27/03/2010 09:49:31 Firewall[7800] Stealth Mode connection attempt to UDP 10.0.1.2:59062 from 10.0.1.1:53
27/03/2010 09:49:31 Firewall[7800] Stealth Mode connection attempt to UDP 10.0.1.2:65046 from 10.0.1.1:53

It seems to happen when loading websites, my understanding is limited, but 10.0.1.1 is the Airport Extreme as far as I know. Is this harmless?

Many thanks for any help.

Michael
__________________
MP '08 2.8 Octo, 4GB, 2 x 1.5Tb, 2 x 750Gb. SL 10.6.2, Powerbook 1.5 1GB, 100Gb Leopard. iPhone 3G 8Gb.
multimania is offline   0 Reply With Quote
Old Mar 27, 2010, 04:59 AM   #2
spinnerlys
Guest
 
Join Date: Sep 2008
Location: forlod bygningen
DNS primarily uses User Datagram Protocol (UDP) on port number 53 to serve requests. DNS queries consist of a single UDP request from the client followed by a single UDP reply from the server. The Transmission Control Protocol (TCP) is used when the response data size exceeds 512 bytes, or for tasks such as zone transfers. Some operating systems, such as HP-UX, are known to have resolver implementations that use TCP for all queries, even when UDP would suffice.
from http://en.wikipedia.org/wiki/Domain_Name_System
via http://www.google.com/search?client=...JJKpsQaTuaTBDg
spinnerlys is offline   0 Reply With Quote
Old Mar 27, 2010, 05:02 AM   #3
multimania
Thread Starter
macrumors member
 
Join Date: Nov 2007
Thank you for that! So can i assume it's ok then?
__________________
MP '08 2.8 Octo, 4GB, 2 x 1.5Tb, 2 x 750Gb. SL 10.6.2, Powerbook 1.5 1GB, 100Gb Leopard. iPhone 3G 8Gb.
multimania is offline   0 Reply With Quote
Old Mar 27, 2010, 01:31 PM   #4
Queso
macrumors 603
 
Join Date: Mar 2006
Basically you're seeing a late DNS response which is being dropped because you have Stealth Mode enabled. Because your router (10.0.1.1) isn't really a DNS server it has to forward all requests from your Mac (10.0.1.2) out to your ISP's DNS servers, which also may have to forward the requests on further if they cannot resolve the name to an address themselves. Sometimes the responses take longer than your Mac expects so the firewall closes the connection the request was made on, meaning the returned packet is rejected. The rest of the output is how they get logged by OSX.

Don't worry about it. It's normal behaviour.
Queso is offline   0 Reply With Quote
Old Apr 11, 2012, 09:26 PM   #5
KRDHarris
macrumors newbie
 
Join Date: Mar 2004
How can I turn of “bings” resulting from stealth mode connection attempts?

Thanks for the explanation Queso, but a few weeks ago I started hearing “bings” from my iMac, (including when it was asleep), that I eventually tracked down to the same stealth mode connection attempt as reported in this thread.

I thus have two questions:

(1) How can I turn off the “bings”, as I can see no relevant setting in Firewall preferences?

(2) (Less important, unless no solution to (1))
What might have changed on my iMac to cause this phenomenon to start? (I cannot think of anything relevant that I have changed recently.)

Environment:
27” iMac
2.93 GHz Intel Core i7
12 GB SDRAM
Mac OS X 10.7.3

Thank you
________________________

Quote:
Originally Posted by Queso View Post
Basically you're seeing a late DNS response which is being dropped because you have Stealth Mode enabled. Because your router (10.0.1.1) isn't really a DNS server it has to forward all requests from your Mac (10.0.1.2) out to your ISP's DNS servers, which also may have to forward the requests on further if they cannot resolve the name to an address themselves. Sometimes the responses take longer than your Mac expects so the firewall closes the connection the request was made on, meaning the returned packet is rejected. The rest of the output is how they get logged by OSX.

Don't worry about it. It's normal behaviour.
KRDHarris is offline   0 Reply With Quote

Reply
MacRumors Forums > Apple Systems and Services > OS X

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
thread Thread Starter Forum Replies Last Post
Firewall and odd behavior? Starhorsepax Mac Basics and Help 0 Jul 27, 2011 12:19 AM
Internet problems and "Stealth Mode connection attempt to TCP" Shoto OS X 1 Jan 19, 2010 09:13 PM
FYI: Stealth Mode connection attempt s2mcpaul OS X 0 Sep 8, 2009 12:38 AM
disable one port of firewall for hosting adrusi Web Design and Development 8 Jul 17, 2009 11:43 AM
Opening port in firewall stoneage OS X 0 Jul 11, 2006 09:32 PM


All times are GMT -5. The time now is 10:17 PM.

Mac Rumors | Mac | iPhone | iPhone Game Reviews | iPhone Apps

Mobile Version | Fixed | Fluid | Fluid HD
Copyright 2002-2013, MacRumors.com, LLC